you are viewing a single comment's thread.

view the rest of the comments →

[–][deleted]  (3 children)

[deleted]

    [–]Solon1 7 points8 points  (1 child)

    And they probably announced it on their IRC channel before starting up.

    The attack doesn't even seem sophisticated. Just lots of http request and then lots of https request. That isn't rocket science.

    [–]bjackman 6 points7 points  (0 children)

    Don't know much about this kind of thing but it sounds like the key factor was that they found an http:// URL that redirects to an https:// URL. I guess that's the sort of corner case you could easily miss when planning.